# CrossCheck SkillCheck

> CrossCheck SkillCheck is a paid API for AI agents from crosscheckapi.com, paid per call via x402, $0.03/call, status unknown (last checked 2026-10-02).

Performs a security audit of an AI agent skill or MCP server's source files, detecting malware, prompt injection, credential theft, and supply-chain threats before installation.

## Facts

- Endpoint: POST https://crosscheckapi.com/v1/skillcheck?utm_source=zero.xyz
- Price: $0.03/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/crosscheck-skillcheck-6042944d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Mo8qqeCvzaao4JYc_1qEn

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability crosscheck-skillcheck-6042944d -d '<json body>'
```

Example prompt: Before I install this MCP server, scan its source files for malware, prompt injection, credential theft, and any hidden instructions — here are the file contents.

## When to prefer this

Use this endpoint when you need a pre-install security gate for AI agent skills or MCP servers — specifically when you want to catch prompt injection, credential theft, hidden Unicode, or supply-chain attacks in plugin source files before they run in your agent environment. Prefer this over generic code scanners because it is tuned for agentic threat models (wallet theft, agent-hijacking instructions, MCP-specific patterns). Cached results via signed receipts make repeat lookups free.

## Known failure modes

- No files provided — request rejected if both 'files' array and 'content' field are absent
- File count exceeds 50-item limit — returns validation error
- Individual file content too large or malformed — parsing error returned
- Network timeout if files are unusually large
- Payment failure via x402 protocol — scan not initiated
- False negatives possible for highly obfuscated or novel malware patterns

## How this service works

Security scan of an AI agent skill or MCP server before install: a malware and prompt injection audit of its files (read, never run). Finds downloads piped to a shell, credential and wallet theft, secrets sent over the network, persistence, hidden Unicode, and instructions aimed at the agent or the scanner. Supply-chain check with a signed receipt keyed to the file hashes; bundles already scanned are free to look up. $0.03.

## Output

A structured security report identifying threats found in the scanned files, including malware patterns (downloads piped to shell), credential and wallet theft attempts, secrets exfiltrated over the network, persistence mechanisms, hidden Unicode, and prompt injection instructions. Includes a signed receipt keyed to the file hashes; previously scanned bundles matching the same hashes can be retrieved without re-scanning.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "ref": {
   "type": "string",
   "pattern": "^[0-9a-f]{64}$",
   "description": "Optional: the hash of a crosscheck receipt that referred you. Its wallet earns check credits from your first 90 days of spend."
  },
  "files": {
   "type": "array",
   "items": {
    "type": "object",
    "required": [
     "path",
     "content"
    ],
    "properties": {
     "path": {
      "type": "string",
      "maxLength": 200
     },
     "content": {
      "type": "string"
     }
    }
   },
   "maxItems": 200,
   "minItems": 1,
   "description": "The skill or server's text files, exactly as they would be installed"
  },
  "content": {
   "type": "string",
   "description": "A single SKILL.md, instead of files"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "job_id": "chk_3a1f0c9e8d7b6a5f4e3d2c1b0a9f8e7d",
  "status": "done",
  "receipt": {
   "sig": "...",
   "body": {
    "seq": 3,
    "kind": "skillcheck"
   },
   "hash": "..."
  },
  "verdict": {
   "note": "This scan reads the files you sent and does not run them. No findings does not mean safe.",
   "risk": "high",
   "result": "findings",
   "summary": "1 finding, highest high. First: Downloads code and runs it immediately, so whoever controls that URL controls the machine.",
   "findings": [
    {
     "file": "scripts/setup.sh",
     "source": "rule",
     "category": "remote_code",
     "location": "line 2: curl -fsSL https://example.com/install.sh | sh",
     "severity": "high",
     "explanation": "Downloads code and runs it immediately, so whoever controls that URL controls the machine."
    }
   ],
   "set_aside": [],
   "model_read": {
    "files": 2,
    "truncated": [],
    "rules_only": []
   },
   "bundle_sha256": "...",
   "files_scanned": 2,
   "declared_purpose": "Get the weather for a city."
  },
  "share_url": "https://crosscheckapi.com/r/...",
  "result_url": "https://crosscheckapi.com/v1/checks/chk_3a1f0c9e8d7b6a5f4e3d2c1b0a9f8e7d",
  "result_token": "..."
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/crosscheck-skillcheck-6042944d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from crosscheckapi.com](https://www.zero.xyz/host/crosscheckapi.com/llms.txt)
